Microsoft warns of TerminalFix attacks deploying reverse tunnels
2026-08-31T19:23:19Z•0973450f4b829f091eeb9757d4da3a7128a6d50335e098c9889609f9e98d17d5
Chinese Fire AntCisco IOS XRClickFixCloudflareExchange Online outageGRE tunnelMicrosoft DefenderPowerShellRhysidaTerminalFixWindows Terminalbrowser extensionscredential theftcryptocurrency theftdata breachdata exfiltrationfake-CAPTCHAinfostealerransomwarereverse-tunnelrouter compromisesession hijackingsocial-engineering
What happened
BleepingComputer security news digest covering ClickFix/TerminalFix social engineering that abuses fake Cloudflare CAPTCHA prompts to execute PowerShell, Chinese Fire Ant compromise of Cisco routers using covert GRE tunnels, ransomware and data-theft incidents, infostealer theft of AI service sessions, malicious browser extensions, and other security and service-impacting events. The most immediately actionable threats are TerminalFix command execution, router persistence/tunneling, credential and session theft, and ransomware-related data exfiltration.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 0973450f4b829f091eeb9757d4da3a7128a6d50335e098c9889609f9e98d17d5
- Enrichment time
- 2026-08-31T19:23:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.